top of page

Exhibit C — List of Sub-Processors

Vee Inc. (“Company”) engages the sub-processors below to process Customer Data in connection with the Services. This list supports Section 36 of the MSA and the Data Processing Addendum. Draft for legal review — confirm entity names, regions, and the conditional items before publishing.

1. Sub-Processors

Purpose / Processing Activity
Categories of Personal Data
Sub-Processor
Location
Cloud hosting, database (Cloud SQL / Postgres), storage, and AI/LLM inference via Vertex AI (Gemini)
All Customer Data stored or processed in the Platform; prompt content
Google LLC (Google Cloud Platform)
European Union (Belgium, europe-west1)
LLM inference — Anthropic Claude models via AWS Bedrock
Prompt content (may include Personal Information submitted by Users)
Amazon Web Services, Inc.
United States & European Union (multi-region)
LLM inference — OpenAI models via Azure OpenAI Service
Prompt content (may include Personal Information submitted by Users)
Microsoft Corporation
United States & European Union (multi-region)
Vector database for customer-uploaded content (predominantly public data)
Customer-uploaded content; embeddings
Pinecone Systems, Inc.
United States [confirm]
Graph database for customer-uploaded content (predominantly public data)
Customer-uploaded content
Neo4j, Inc. (AuraDB)
United States (GCP us-central1, Iowa)
Authentication / identity management
User names, email addresses
SuperTokens
European Union (AWS eu-west-1)
Payment and subscription processing
Billing contact details; payment metadata
Stripe, Inc.
United States
CRM, transactional email / SMTP, and notifications
Contact names, email addresses, message content
HubSpot, Inc.
United States
Email & calendar connectivity; stores Google / Microsoft 365 OAuth tokens
OAuth tokens; email & calendar metadata and content
Nylas, Inc.
United States
Product analytics
Usage data, user identifiers
PostHog, Inc.
United States
Application logging and observability
Log and telemetry data (may include identifiers)
Coralogix Ltd.
European Union
LLM tracing and observability
Prompt traces (may include Personal Information)
Langfuse GmbH
United States
Automated browsing / scraping sessions
Web content; customer inputs as applicable
Browser Use
United States
URL shortening
URLs (personalized links may be Personal Information)
TinyURL LLC
United States
Content delivery network (edge caching/delivery)
Traffic metadata, including IP addresses
Fastly, Inc.
Global edge network

Note on LLM routing: Under AWS Bedrock, Azure OpenAI, and Vertex AI, the foundation-model developers (Anthropic, OpenAI, Google) do not receive Customer Data — the cloud provider is the processor. None of these services train on Customer Data, consistent with Section 37 (No Training on Customer Data).

2. Customer-Authorized Integrations (NOT Sub-Processors)

These are connected by the Customer to the Customer’s own third-party accounts, and data flows at the Customer’s direction. They are the Customer’s processors/recipients, not Vee’s sub-processors. Disclosed here for transparency.

Integration
Nature of Access
Data Owned/Controlled By
Gmail (Google)
Customer-authorized mailbox access (via Nylas), at the User’s direction
Customer’s own email account
Microsoft 365 / Outlook
Customer-authorized mailbox access (via Nylas), at the User’s direction
Customer’s own email account
Givebutter (via Donna)
Customer-authorized fundraising-platform integration, at the User’s direction
Customer’s own Givebutter account
Social / grant platforms (e.g., Facebook, Instagram, grant portals)
Publishing destinations the Customer directs content to
Customer’s own platform accounts

Reminder: Nylas (which stores the OAuth tokens for Gmail / Microsoft 365) IS Vee’s sub-processor and appears in Section 1; the mailboxes themselves are customer-controlled integrations and appear here.

Prepared as a working draft. Not legal advice — counsel should confirm before this is published at vee.com/legal/subprocessors or inserted into the DPA.

bottom of page